Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
[
{
"source": "https://github.com/gpac/gpac/commit/2da2f68bffd51d89b1d272d22aa8cc023c1c066e",
"target": {
"file": "src/isomedia/stbl_read.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2021-31256-05ee90d3",
"digest": {
"threshold": 0.9,
"line_hashes": [
"271379964838622770638191838537824836551",
"74850478146093276797840713117210784655",
"21002431492837768195116458944965376348",
"10439252769331870000504154050764030868",
"270499913990714120200417959583955387157",
"71653203197305157759355907345428642969",
"192356018987768621237434183887153868824",
"30849309437551593067950658740262982675"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/gpac/gpac/commit/2da2f68bffd51d89b1d272d22aa8cc023c1c066e",
"target": {
"function": "stbl_GetSampleInfos",
"file": "src/isomedia/stbl_read.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2021-31256-83bd733c",
"digest": {
"length": 4707.0,
"function_hash": "178363004142591669781357107860031073898"
},
"signature_type": "Function"
}
]